Courseiva

CEH Footprinting and Reconnaissance Practice Question

During an authorized external assessment, a tester wants to determine which mail exchangers and third-party SaaS providers a target uses without alerting the target's security team. The tester already knows the primary domain. Which single command best reveals the target's MX records using a public resolver while sending no traffic to the target itself?

⚠ Common exam trap

The trap here is thinking that any DNS query is passive, when choosing the target's own name server as the resolver still sends traffic to infrastructure the target controls and can monitor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dig @8.8.8.8 target.com MX +noall +answer

Directing a DNS query to a public resolver such as 8.8.8.8 keeps the request off the target's systems while still returning the MX records needed to identify mail and SaaS providers. The +noall +answer flags trim the output to just the relevant records, making the result easy to parse, and the technique leaves no footprint on target-owned name servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    dig target.com ANY @target.com

    Why it's wrong here

    Sending an ANY query to the target's own domain name server contacts target-controlled infrastructure directly, which is active and could be logged or rate-limited. Modern resolvers also frequently refuse ANY queries to mitigate amplification abuse, so the result is unreliable. It fails both the passive requirement and the goal of cleanly isolating MX records.

  • ✗

    host -t MX target.com 10.0.0.53

    Why it's wrong here

    This command targets a private RFC 1918 address, which is almost certainly unreachable from the tester's external vantage point and is not a valid public resolver. Even if it resolved, the query would be sent to an internal DNS server, which contradicts the requirement to avoid touching target-owned infrastructure and would likely return no useful answer.

  • ✓

    dig @8.8.8.8 target.com MX +noall +answer

    Why this is correct

    This command queries Google's public resolver at 8.8.8.8 for the domain's MX records and displays only the answer section. The DNS request goes to the resolver, not to any hospital-controlled server, so it remains passive relative to the target. The MX records then reveal mail providers and sometimes SaaS tenants, exactly the intelligence required.

  • ✗

    nslookup -type=MX target.com ns1.target.com

    Why it's wrong here

    Specifying ns1.target.com as the server directs the query to the target's own authoritative name server. Although the query is small, it still reaches target-owned infrastructure and can be logged, breaking the passive constraint. The MX data returned would be accurate, but the method fails the requirement to avoid alerting the target's security team.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.